Characterizing and Measuring Maliciousness for Cybersecurity Risk Assessment

被引:23
|
作者
King, Zoe M. [1 ]
Henshel, Diane S. [1 ]
Flora, Liberty [1 ]
Cains, Mariana G. [1 ]
Hoffman, Blaine [2 ]
Sample, Char [2 ,3 ]
机构
[1] Indiana Univ, Sch Publ & Environm Affairs, Bloomington, IN 47405 USA
[2] Army Res Lab, Aberdeen, MD USA
[3] Army Res Lab, Adelphi, MD USA
来源
FRONTIERS IN PSYCHOLOGY | 2018年 / 9卷
关键词
human risk factors; malicious intent; cyber security; cyber terrorism; rational behavior; metrics; motivation; DARK TRIAD; CULTURE; PERSONALITY; AGGRESSION; BEHAVIOR;
D O I
10.3389/fpsyg.2018.00039
中图分类号
B84 [心理学];
学科分类号
04 ; 0402 ;
摘要
Cyber attacks have been increasingly detrimental to networks, systems, and users, and are increasing in number and severity globally. To better predict system vulnerabilities, cybersecurity researchers are developing new and more holistic approaches to characterizing cybersecurity system risk. The process must include characterizing the human factors that contribute to cyber security vulnerabilities and risk. Rationality, expertise, and maliciousness are key human characteristics influencing cyber risk within this context, yet maliciousness is poorly characterized in the literature. There is a clear absence of literature pertaining to human factor maliciousness as it relates to cybersecurity and only limited literature relating to aspects of maliciousness in other disciplinary literatures, such as psychology, sociology, and law. In an attempt to characterize human factors as a contribution to cybersecurity risk, the Cybersecurity Collaborative Research Alliance (CSec-CRA) has developed a Human Factors risk framework. This framework identifies the characteristics of an attacker, user, or defender, all of whom may be adding to or mitigating against cyber risk. The maliciousness literature and the proposed maliciousness assessment metrics are discussed within the context of the Human Factors Framework and Ontology. Maliciousness is defined as the intent to harm. Most maliciousness cyber research to date has focused on detecting malicious software but fails to analyze an individual's intent to do harm to others by deploying malware or performing malicious attacks. Recent efforts to identify malicious human behavior as it relates to cybersecurity, include analyzing motives driving insider threats as well as user profiling analyses. However, cyber-related maliciousness is neither well-studied nor is it well understood because individuals are not forced to expose their true selves to others while performing malicious attacks. Given the difficulty of interviewing malicious-behaving individuals and the potential untrustworthy nature of their responses, we aim to explore the maliciousness as a human factor through the observable behaviors and attributes of an individual from their actions and interactions with society and networks, but to do so we will need to develop a set of analyzable metrics. The purpose of this paper is twofold: (1) to review human maliciousness-related literature in diverse disciplines (sociology, economics, law, psychology, philosophy, informatics, terrorism, and cybersecurity); and (2) to identify an initial set of proposed assessment metrics and instruments that might be culled from in a future effort to characterize human maliciousness within the cyber realm. The future goal is to integrate these assessment metrics into holistic cybersecurity risk analyses to determine the risk an individual poses to themselves as well as other networks, systems, and/or users.
引用
收藏
页数:19
相关论文
共 50 条
  • [1] Towards Supercomputing Categorizing the Maliciousness upon Cybersecurity Blacklists with Concept Drift
    Carriegos, M. V.
    DeCastro-Garcia, N.
    Escudero, D.
    COMPUTATIONAL AND MATHEMATICAL METHODS, 2023, 2023
  • [2] Cybersecurity risk assessment of VDR
    Soner, Omer
    Kayisoglu, Gizem
    Bolat, Pelin
    Tam, Kimberly
    JOURNAL OF NAVIGATION, 2023, 76 (01): : 20 - 37
  • [3] Semantic Risk Assessment for Cybersecurity
    Aviad, Adiel
    Wecel, Krzysztof
    Abramowicz, Witold
    PROCEEDINGS OF THE 13TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS 2018), 2018, : 513 - 520
  • [4] Cybersecurity Risk Assessment for Space Systems
    Vessels, Ly
    Heffner, Kenneth
    Johnson, Daniel
    2019 IEEE SPACE COMPUTING CONFERENCE (SCC), 2019, : 11 - 19
  • [5] A Systems Approach for Cybersecurity Risk Assessment
    Meshkat, Leila
    Miller, Robert L.
    2022 68TH ANNUAL RELIABILITY AND MAINTAINABILITY SYMPOSIUM (RAMS 2022), 2022,
  • [6] Digital Human in Cybersecurity Risk Assessment
    Jureviciene, Aiste
    Brilingaite, Agne
    Bukauskas, Linas
    AUGMENTED COGNITION, AC 2021, 2021, 12776 : 418 - 432
  • [7] Characterizing cybersecurity jobs: Applying the Cyber Aptitude and Talent Assessment Framework
    Campbell, Susan G.
    Saner, Lelyn D.
    Bunting, Michael F.
    SYMPOSIUM AND BOOTCAMP ON THE SCIENCE OF SECURITY, 2016, : 25 - 27
  • [8] A Systematic Risk Assessment Framework of Automotive Cybersecurity
    Wang, Yunpeng
    Wang, Yinghui
    Qin, Hongmao
    Ji, Haojie
    Zhang, Yanan
    Wang, Jian
    AUTOMOTIVE INNOVATION, 2021, 4 (03) : 253 - 261
  • [9] A simulation framework for automotive cybersecurity risk assessment
    Jayaratne, Don Nalin Dharshana
    Kamtam, Suraj Harsha
    Shaikh, Siraj Ahmed
    Ramli, Muhamad Azfar
    Lu, Qian
    Mepparambath, Rakhi Manohar
    Nguyen, Hoang Nga
    Rakib, Abdur
    SIMULATION MODELLING PRACTICE AND THEORY, 2024, 136
  • [10] Cybersecurity Risk Assessment in Smart City Infrastructures
    Kalinin, Maxim
    Krundyshev, Vasiliy
    Zegzhda, Peter
    MACHINES, 2021, 9 (04)